Daggerfly
MITRE ATT&CK: G1034 View on attack.mitre.org
Aliases: Evasive Panda, BRONZE HIGHLAND, Daggerfly, Daggerfly
- First seen
- 2012-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 17 (3 malicious)
- Last IoC activity
- 2026-08-02 15:55:12
- Profile updated
- 2026-07-07 12:02:36
Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications
Targeted regions: country_code:cn country_code:in country_code:ke
Context
Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.
Recent IoC activity
3 malicious indicators in Maltiverse are attributed to Daggerfly (G1034). The 3 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | Snipaste.exe | 2026-08-02 | 2 |
| file sample | audio | 2025-10-21 | 2 |
| file sample | clipboard capture | 2025-08-31 | 2 |
Detection coverage
- 16 YARA rules
- 537 Sigma rules
Malware & tools used
- Code Signing Certificates (attack-pattern)
- Scheduled Task (attack-pattern)
- Web Protocols (attack-pattern)
- PowerShell (attack-pattern)
- Rename Legitimate Utilities (attack-pattern)
- Malicious Link (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Information Discovery (attack-pattern)
- Compromise Software Supply Chain (attack-pattern)
- DLL (attack-pattern)
- Rundll32 (attack-pattern)
- Server (attack-pattern)
- Local Account (attack-pattern)
- Code Signing (attack-pattern)
- Query Registry (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Security Account Manager (attack-pattern)
- Nightdoor (malware)
- BITSAdmin (malware)
- PlugX (malware)
- MgBot (malware)
- MacMa (malware)
- Reg (malware)
Reports & references
- blog.malwarebytes.com — Chinese Apt Group Targets India And Hong Kong Using New Variant Of Mgbot Malware (report)
- vb2020.vblocalhost.com — Vb2020 43 (report)
- youtube.com — Watch (report)
- ESET — Evasive Panda Apt Group Malware Updates Popular Chinese Software (report)
- virusbulletin.com — Needle Haystack (report)
- MITRE ATT&CK — G1034 (report)
- Broadcom/Symantec — Apt Attacks Telecoms Africa Mgbot (report)
- Broadcom/Symantec — Daggerfly Espionage Updated Toolset (report)
- ESET — Evasive Panda Leverages Monlam Festival Target Tibetans (report)